---
sourceDocument: Store Version History Release Notes
sourceDocumentLink: https://www.servicenow.com/docs/r/store-release-notes

 Release :

    - store

ft:locale :

    - en-US

ft:publication_title :

    - Store Version History Release Notes

ft:clusterId :

    - rnst

bundleId :

    - rnst


---

# DLP Incident Response integration with Microsoft release notes

# DLP Incident Response integration with Microsoft release notes {#ariaid-title1}

Release version: Store  
Updated October 8, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of DLP Incident Response integration with Microsoft release notes

The DLP Incident Response integration with Microsoft provides a comprehensive framework to import and manage Data Loss Prevention (DLP) incidents from various Microsoft Purview sources, including Teams, SharePoint, email, endpoint, network, and cloud environments.
It supports automated remediation workflows, incident assignment, escalations, and communication templates for end-user coaching.
This integration enhances visibility and control over DLP incidents within ServiceNow Security Operations.
Show full answer Show less  

## Key Features and Enhancements

* **Incident Ingestion and Management:** Continuous improvements to ensure reliable ingestion of Microsoft DLP incidents, including performance optimizations, error handling, and support for multiple Microsoft environments like GCC, Commercial, DOD, and GCC-High.
* **Storage and Evidence Handling:** Support for internal and external evidence file storage, including Azure Blob Storage and Amazon S3, with secure, instance-specific file naming to prevent conflicts across multiple ServiceNow instances. Users can preview and download evidence files directly within the DLP Workspace.
* **Release from Quarantine:** Enhanced handling of email release from quarantine with fixes to error states and improved PowerShell dependency support, ensuring smoother quarantine workflows.
* **Read-Only Field Enforcement:** Dictionary-level fields upgraded to strict read-only to prevent unauthorized modifications across UIs, scripts, and integrations.
* **Endpoint Integration:** Added support for ingesting DLP endpoint alerts and improved endpoint artifact file download by routing requests through the ServiceNow instance IP for consistent access control.
* **Custom Configuration:** Added capabilities such as configurable polling intervals in minutes, and enhanced mapping for user IDs and sensitive information types to tailor integrations to specific organizational needs.
* **Improved User Experience:** Fixed UI issues related to incident details, match count display, and profile settings to enhance analyst usability.

## Key Outcomes for ServiceNow Customers

* **Reliable Multi-Instance Support:** Unique file naming conventions prevent encryption/decryption conflicts when multiple ServiceNow instances connect to the same Microsoft DLP source.
* **Enhanced Security and Compliance:** Strict enforcement of read-only fields and accurate incident data mappings help maintain data integrity and compliance standards.
* **Streamlined Incident Response:** Automated workflows, accurate incident details, and improved quarantine handling accelerate remediation efforts and reduce manual errors.
* **Comprehensive Evidence Management:** Easier access to evidence files through preview and download features supports thorough incident investigations.
* **Optimized Performance:** Ingestion pipeline improvements and enhanced API handling ensure timely processing of incidents even during peak loads.
* **Broader Environment Compatibility:** Support for multiple Microsoft cloud environments ensures the integration can be deployed across diverse organizational setups.  
Version history for the Security Operations DLP Incident Response integration with Microsoft on the ServiceNow Store.
Important:  
For details on system requirements and family compatibility, view the application listing on the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website.

## Version history

Version 1.5.7 - October 2026
:
    * Fixed:
      * Unique Blob Storage File Names for Microsoft DLP
        * Updated the external Blob Storage file naming convention for Microsoft DLP to include instance-specific details. This ensures that when multiple ServiceNow instances are configured to use the same Microsoft DLP source, each instance stores files with unique names, preventing encryption and decryption conflicts across instances.
        {#store-secops-rn-dlp-incident-response-integration-ms__ul_kyc_wpt_rkc}
      {#store-secops-rn-dlp-incident-response-integration-ms__ul_qx5_vpt_rkc}
    * Correct Match Count Display for DLP Endpoint Incidents
      * Resolved an issue where the Match Count field in the Details section of DLP Endpoint incidents always displayed 0, even when a valid Match Count was available in the SIT Info tab. The Details section now correctly displays the actual Match Count.
      {#store-secops-rn-dlp-incident-response-integration-ms__ul_mwl_wpt_rkc}
    {#store-secops-rn-dlp-incident-response-integration-ms__ul_k4g_vpt_rkc}

Version 1.5.5 - September 2026
:   Fixed: Addressed mapping issue during incident ingestion for fields "Detection date Sent" and "File Created".

Version 1.5.3 - July 2026
:   Fixed: Added the PowerShell dependency required to enable the Release Quarantine Email flow.

Version 1.5.2 - June 2026
:   Fixed: The read_only_options attribute has been moved from IF folder--based plugin configuration to dictionary attributes on the table fields.

Version 1.5.1 - May 2026
:
    * Fixed:
      * Access issues for security analysts while querying tables.
      * UI issue in the profile for displaying endpoint evidence file storage type.
      * Field translation issue for keys which has undefined values.
      {#store-secops-rn-dlp-incident-response-integration-ms__ul_yfl_nrc_cjc}

Version 1.5.0 - February 2026
:
    * New: Support internal storage of Match content in Microsoft Purview Integration.
    * Fixed: Prevent permanent data loss by adding support to re-process errored contentURI records.

Version 1.3.1 - January 2026
:   Fixed: Removed redundant ACLs from the Match Content field in the Detected Sensitive Info table.

Version 1.2.0 - December 2025
:   New Upgraded dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes. This update ensures the server consistently enforces read-only behavior across all UIs, scripts, and
    integrations.

Version 1.1.21 - October 2025
:
    Fixed:

    * Release from quarantine feature not functioning when configured with a target state.
    * Added support for Microsoft DLP integration with GCC, Commercial, DOD, and GCC-High environments.
    * Resolved issue where Microsoft DLP integration runs containing empty data were not completing successfully.
    * Improved handling of integration runs where all data in the contentURI is filtered out by profile filters, and implemented timeout handling for contentURI and 'List Available Content' REST calls.
    {#store-secops-rn-dlp-incident-response-integration-ms__ul_v1v_p51_zgc}
    {#store-secops-rn-dlp-incident-response-integration-ms__latest-store-secops-rn-dlp-incident-response-integration-ms}
{#store-secops-rn-dlp-incident-response-integration-ms__latest-store-secops-rn-dlp-incident-response-integration-ms}

Version 1.1.10 - August 2025
:   Fixed: Release Email from Quarantine Failure for DLP Exchange Online.

Version 1.1.2 - July 2025
:
    * Fixed:
      * Microsoft DLP Quarantine Release Error Handling:
        * Resolved an issue where attempting to Release Email from Quarantine for incidents that were already released would cause the DLP Microsoft integration to enter an error state. The system now properly detects already released emails and avoids redundant actions, preventing unnecessary errors in the quarantine flow.
        {#store-secops-rn-dlp-incident-response-integration-ms__ul_ezf_j32_wfc}
      * Enhanced Endpoint File Download via Custom Blob Storage:
        * Updated the file download mechanism for endpoint artifacts from custom blob storage. Previously, requests were made using the user's IP address, which could lead to access issues depending on network rules. With this update, download requests are now routed through the ServiceNow instance IP, ensuring consistent access control and improving compatibility with restricted storage configurations.
        {#store-secops-rn-dlp-incident-response-integration-ms__ul_k52_k32_wfc}
      * Microsoft DLP Ingestion Performance Improvements:
        * Optimized the Microsoft DLP ingestion pipeline to address slow performance during peak usage periods. Enhancements include better concurrency handling, improved API response management, and resource allocation tuning to ensure faster and more reliable ingestion even under high-load conditions.
        {#store-secops-rn-dlp-incident-response-integration-ms__ul_add_k32_wfc}
      {#store-secops-rn-dlp-incident-response-integration-ms__ul_enh_j32_wfc}
    {#store-secops-rn-dlp-incident-response-integration-ms__ul_jcl_332_wfc}

Version 1.1.1 - June 2025
:
    * Fixed:
      * Generation of unnecessary error logs on clicking the Sensitive Information tab in the Workspace.
      * Bug where multiple Sensitive Information Types with the same name were incorrectly created under the Detective Sensitive tab when different conditions were met simultaneously.
      * Limitation where the "Incident Response Option Rule" could not be modified for Out-of-the-Box (OOTB) configurations. Users can now adjust these rules as expected.
      {#store-secops-rn-dlp-incident-response-integration-ms__ul_ggh_1cn_nfc}

Version 1.1.0 - May 2025
:
    * New:
      * Provided support for ingesting DLP Endpoint alerts using Microsoft Purview.
      * Added Purview's user ID field for End User Lookup Rules mapping.
      {#store-secops-rn-dlp-incident-response-integration-ms__ul_et5_ryb_cfc}

Version 1.0.13 - February 2025
:
    * New:
      * Evidence File Preview with Download Option:
        * Added a preview icon for evidence files in the DLP Workspace.
        * Users can now preview evidence files and download them directly from the preview interface, simplifying evidence review and retrieval.
        {#store-secops-rn-dlp-incident-response-integration-ms__ul_qpl_4k2_d2c}
      {#store-secops-rn-dlp-incident-response-integration-ms__ul_gk3_4k2_d2c}
    {#store-secops-rn-dlp-incident-response-integration-ms__ul_o5s_nk2_d2c}

Version 1.0.11 - January 2025
:   Fixed: During upgrades, scheduled import sets were ignored, causing the data source pool to remain occupied. This resulted in ingestion process failures.

Version 1.0.10 - November 2024
:
    * New: The integration now supports Evidence File Storage in ServiceNow, which includes the implementation of Microsoft Evidence File external storage, enabling better management and accessibility of evidence files.
    * Fixed:
      * The Microsoft DLP Incident Profile M2M data mismatch issue, ensuring accurate data representation.
      * The state was not updating correctly during the release from quarantine after a successful process.
      * Match content now appears for incidents archival in Microsoft DLP.
      {#store-secops-rn-dlp-incident-response-integration-ms__ul_ux2_nhw_2dc}

Version 1.0.9 - August 2024
:
    * New: Microsoft is now compatible with the DLP core migration changes such as incident status.
    * Fixed: EnforcementMode field is now available within the incident.

Version 1.0.8 - February 2024
:
    * New: Added correlation ID within the DLP incident table to map the integration ID to the DLP incidents.
    * Fixed:
      * The domain ID (sys_domain) is set to undefined when the DLP incidents are created using the import set API.
      * Enhanced the application logging when a Download File action fails on the DLP incident.
      * The Release quarantine action on the DLP incident updates the state field when the internal PowerShell command fails.
      * Integration run record was stuck during the execution for the incidents that are complete.
      {#store-secops-rn-dlp-incident-response-integration-ms__ul_v4l_1jv_21c}

Version 1.0.5 - December 2023
:
    * Fixed:
      * Resolved the misleading 403 error in the DLPStorageUtilsAzure script include.
      * Fixed the issue where the Since Date validation in the Profile was failing when the user was using a different date-time format.
      * Addressed the issue of parsing of the event failing for Endpoint type of events with no SensitiveInfo.
      * Fixed the missing BCC field in the Microsoft integration transform mappings.
      {#store-secops-rn-dlp-incident-response-integration-ms__ul_f2v_5gs_pzb}

Version 1.0.4 - August 2023
:
    * New: You can now configure the polling interval in minutes instead of hours, for a DLP incident profile.
    {#store-secops-rn-dlp-incident-response-integration-ms__ul_d3k_nk5_gyb}

Version 1.0.2 - June 2023
:
    * Fixed:
      * The Match Content option is now visible in the import set attachments section.
      * The Microsoft Integration Run was getting stuck in the running state when the API returned an error. This issue is now resolved.
      {#store-secops-rn-dlp-incident-response-integration-ms__ul_wtg_kf4_4xb}

Version 1.0.1 - May 2023
:
    * New:
      * Match content per sensitive info type in MSFT Integration and highlight exact matched text in the content.
      * Encrypt match content stored in AWS/Azure and delete automatically.
      * New configuration tile for Azure blob storage and Amazon S3.
      {#store-secops-rn-dlp-incident-response-integration-ms__ul_drc_sgj_mxb}
    * Fixed: Implement integration run for Microsoft DLP integration.

Version 1.0.0 - February 2023
:
    * Provides a core framework to import Data Loss Prevention (DLP) incidents from multiple sources such as Microsoft purview apps (Teams, Sharepoint, Email), endpoint, network, email, and cloud and enables remediation workflow involving end users, managers, and DLP operations team with automated incident assignment and escalations.
    * It allows DLP administrators to configure email templates for end-user coaching and communication and provides comprehensive reporting on incident trends.
    {#store-secops-rn-dlp-incident-response-integration-ms__ul_ztc_tgj_mxb}

